7 ms·
Passwords became hard to manage... now you have to choose >>different<< password for every site... Who can remember all those passwords? Only a password manager
by markokrajnc 10y ago
Passwords became hard to manage... now you have to choose >>different<< password for every site... Who can remember all those passwords? Only a password manager...
- eximius 10y agoWe need to ditch passwords, not continue to proliferate them with sandboxed databases.
- voidz 10y agoYeah? What kind of a secret can replace a password/passphrase? Not biometrics, those are username replacements, not password replacements.
- WillAbides 10y agoChip implants
- ascagnel_ 10y agoHow would that differ as a means of verification? It's not a known secret, just a different way of identification.
- milesokeefe 10y agoNot if the implant is writable. The xNT 13.56mhz NTAG216 RFID implant has 888 bytes of writable memory that could be used in this way.
- malka 10y agosmartcards would be good for this.
- marcosdumay 10y agoKeys. That are approximately equivalent to long passwords, but have a standard length, and do not need sending through the network. They are also something you have, that can be protected by a password for 2FA. But that just won't happen. So many sites can not even accept big passwords, they won't all migrating to any sane schema.
- 794CD01 10y agoThey are password replacements in most contexts. The point of a password is usually just to verify your identity. Biometrics can do that just fine.
- charonn0 10y agoBiometrics are good replacements for usernames, but not for passwords. Biometrics can't be changed in the event of a breach, and can be taken from you surreptitiously or by force.
- 794CD01 10y agoYes, and those features are not necessary in most scenarios passwords are currently used.
- infogulch 10y agoBiometrics can be fooled, and even if they couldn't they can only verify your identity. They can't verify your volition.
- 794CD01 10y agoThey can be fooled now, but that is an implementation flaw, not a problem with the concept. I wouldn't cite the weakness of unsalted MD5 hashes as a problem with the concept of passwords. I agree with your assessment of what biometrics can and cannot do. That is why I specifically said that in most situations, passwords are only used to verify someone's identity, and thus can be replaced with biometrics.
- austerity 10y agoShameless plug time! Instead of remembering different passwords or using a password manager (and thus storing all your passwords somewhere) you can use https://salty.pw/ https://salty.pw/
- spion 10y agoThats cool! Does it use simple concatenation or HMAC?
- austerity 10y agoIt's simple concatenation. The exact algorithm is described at the bottom of the page so that one could reproduce it (and their passwords) independently.
- spion 10y agoWhat about taking the 128 MSB vs 128 LSB, is there any research into how secure that is?
- austerity 10y agoI vaguely remember giving it some consideration. But the bigger point is that my judgement on these things is not to be trusted since I'm just an application developer and not a crypto expert.
- spion 10y agoYeah thats the thing, I'm not a crypto expert either but I'd love to use it. But if it gets popular, and there is an accidental mistake that actually makes it easy to guess passwords, I don't want to risk that happening.
- spion 10y agoGood news. Did a bit of investigation, it seems like this could be vulnerable to a length extension attack [1] (though the attack its still pretty useless in this particular case) but it appears that truncating is both safe and takes care of length extension attacks! [2] [1]: https://en.wikipedia.org/wiki/Length_extension_attack https://en.wikipedia.org/wiki/Length_extension_attack [2]: https://crypto.stackexchange.com/questions/18606/is-xoring-a-sha256-better-than-truncating-it https://crypto.stackexchange.com/questions/18606/is-xoring-a...
- wtbob 10y agoIt's really not hard. Generate passwords with 'pwgen -s 22' and store them in a gpg-encrypted file. emacs will prompt for your password when you open & when you save the file (there's probably vim code to do the same). Done. It's not a completely ideal password manager, but it works. If you can remember your password, then you shouldn't be typing it into a remote system, period.
- DasIch 10y agoThat's really an awful solution compared to something like 1Password which has browser integration and synchronization between different devices. They even have a solution for groups.